I've seen a few posts by users claiming to use randomly generated unique passwords. If that's true then it could be a leak from apple. On the other hand it could also be that it's not and the security response team is catching users not on that leaked list due to unrefined heuristics.
On the third hand it is an apple leak, they've been given a sample list by whoever is ransoming them so they've enacted overly strict heuristics that apply to everyone.
On the third hand it is an apple leak, they've been given a sample list by whoever is ransoming them so they've enacted overly strict heuristics that apply to everyone.